CVE-2025-70023
Access of Resource Using Incompatible Type in transloadit uppy v
Publication date: 2026-04-14
Last updated on: 2026-04-16
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| transloadit | uppy | 0.25.6 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-843 | The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type. |
Attack-Flow Graph
AI Powered Q&A
What immediate steps should I take to mitigate this vulnerability?
The provided information does not include any recommended mitigation steps or immediate actions to address this vulnerability.
Can you explain this vulnerability to me?
This vulnerability is related to CWE-843, which involves accessing a resource using an incompatible type. Specifically, it was discovered in transloadit uppy version 0.25.6. This means that the software may attempt to access or manipulate data or resources in a way that is not compatible with their expected type, potentially leading to unexpected behavior or security issues.
How can this vulnerability be detected on my network or system? Can you suggest some commands?
There is no specific information provided about detection methods or commands to identify this vulnerability on your network or system.
How can this vulnerability impact me? :
Exploiting this vulnerability could allow an attacker to cause the application to behave incorrectly by accessing resources with incompatible types. This might lead to application crashes, data corruption, or unauthorized access depending on how the resource is used within the application.
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
CVE-2025-70023 is an Access of Resource Using Incompatible Type vulnerability in transloadit uppy v0.25.6 that allows attackers to potentially access or manipulate resources in unintended ways due to improper handling of resource types.
However, there is no specific information provided about how this vulnerability impacts compliance with common standards and regulations such as GDPR or HIPAA.